Impact
A cryptographic flaw was identified in the integrity checks of Apple’s operating systems. The vulnerability allows an attacker with a privileged network position to modify intercepted traffic, potentially inserting or altering data before it reaches the target device. This weakness undermines the confidentiality and integrity of communications on the affected systems.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, and watchOS are impacted. The bug is resolved in the 27th revision of each platform: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score is not provided, and no EPSS data is available, so the quantified likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. An attacker must have foothold in a privileged network segment to use this flaw, suggesting a limited but non‑negligible attack surface. The potential impact is the ability to tamper with network traffic destined for or originating from Apple devices, which could lead to data injection or compromise of secure communications.
OpenCVE Enrichment